UAC-0050

First seen
2020-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 11:48:57

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine. They have been distributing the Remcos RAT malware through phishing campaigns, using tactics such as impersonating the Security Service of Ukraine and sending emails with malicious attachments. The group has also been linked to other hacking collectives, such as UAC-0096, and has previously used remote administration tools like Remote Utilities. The motive behind their attacks is likely espionage.

Reports & references

  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • CERT-UA — 3931296 (report)
  • socprime.com — Remcos Rat Detection Uac 0050 Hackers Launch Phishing Attacks Impersonating The Security Service Of Ukraine (report)
  • socprime.com — New Phishing Attack Detection Attributed To The Uac 0050 And Uac 0096 Groups Spreading Remcos Spyware (report)
  • CERT-UA — 3804703 (report)

External references